• Home
  • About
  • Services
    • India Entry Services
    • Virtual CFO Services
    • Corporate Secretarial & FEMA
    • Direct & Indirect Taxation
    • Licensing and Registration
    • Secretarial & Corporate Legal Compliances
    • Mergers & Acquisitions (M&A) Services in India
  • Our Team
  • Blog
  • Contact
    • Home
    • About
    • Services
      • India Entry Services
      • Virtual CFO Services
      • Corporate Secretarial & FEMA
      • Direct & Indirect Taxation
      • Licensing and Registration
      • Secretarial & Corporate Legal Compliances
      • Mergers & Acquisitions (M&A) Services in India
    • Our Team
    • Blog
    • Contact
Corporate legit
Corporate legit
  • Home
  • About
  • Services
    • India Entry Services
    • Virtual CFO Services
    • Corporate Secretarial & FEMA
    • Direct & Indirect Taxation
    • Licensing and Registration
    • Secretarial & Corporate Legal Compliances
    • Mergers & Acquisitions (M&A) Services in India
  • Our Team
  • Blog
  • Contact
Request Price

Internal Financial Controls in India: What Boards Actually Owe Under Section 134(5)(e)

Corporate legit > Audit Services in India > Internal Financial Controls in India: What Boards Actually Owe Under Section 134(5)(e)
Internal Financial Controls India
  • August 24, 2026
  • Sachin Aggrawal
  • Audit Services in India
  • 0

Table of Content

  • 1. What counts as an internal financial control under the Companies Act?
  • 2. Which companies have to comply with internal financial controls India rules?
  • 3. What is the board actually responsible for here?
  • 4. What does the statutory auditor check under IFC audit s?
  • 5. What framework should companies actually build on?
  • 6. What happens when internal financial controls in India requirements aren't met?
  • 7. Conclusion

Most Indian Company boards think they’ve handled this. They haven’t.Internal Financial Controls India, Section 134(5)(e) of the Companies Act 2013 asks directors to state, in writing, that internal financial controlsto be followed by the company and that such controls are adequate and were operating effectively.. Not that a policy document exists somewhere in a shared drive. That the controls operate.

That gap between “we have a policy” and “the policy is followed” is where audits fall apart. Internal financial controls in India isn’t a governance buzzword you sprinkle into an annual report. It’s a statutory declaration with a penalty attached if it turns out to be false, and an auditor sitting across the table checking whether it’s true.

What counts as an internal financial control under the Companies Act?

Section 134(5)names six things: orderly and efficient conduct of business, adherence to policies, safeguarding assets, prevention and detection of frauds and errors ,accurate accounting records, and timely preparation of reliable financial reporting.

That’s a wider than most CFOs assume. It’s not just about whether the ledger closes cleanly. Operational discipline counts. So does whether employees actually follow the policies written for them, not just whether the policies exist.

The word that trips people up is “effectively.” Plenty of companies can produce a binder: approval matrices, sign-off chains, delegation charts. What the law wants isevidence, that controls were operating effectively. An approval workflow that gets skipped every time someone’s in a hurry isn’t a working control, no matter how good it looks on paper.

Which companies have to comply with internal financial controls India rules?

Section 134(5)(e) expressly applies to listed companies. In addition, Rule 8(5)(viii) of the Companies (Accounts) Rules, 2014 , requires every listed company, plus unlisted public companies to disclose in board report. . Private companies only if they’re subsidiaries of listed entities or fall into that prescribed bracket.

Company TypeIFC AppliesAuditor Must Report
Listed CompanyYes, mandatoryYes
Unlisted Public Company (prescribed)YesYes
Private Ltd, subsidiary of listed coYesYes
Private Ltd, standalone (prescribed)Not mandatory Depends on applicable exemptions
Small Company (Sec 2(85))ExemptExempt
One Person CompanyExemptExempt

The small company carve-out arrived through the Companies (Amendment) Act 2017. Cross either threshold, paid-up capital above Rs. 10 crore or turnover above Rs. 100 crore, and the exemption disappears. For foreign-owned subsidiaries, as it falls under non-small Company, running lean, this is worth checking every year, not assuming once and forgetting.

What is the board actually responsible for here?

The board signs a statement claiming it built the controls, that they’re adequate, and that they work. Not a summary of what the auditor found. A claim the board makes on its own authority.

This is the part boards keep getting wrong. Signing the Directors’ Responsibility Statement isn’t a formality that happens after the CFO’s team quietly does the real work. The board can’t outsource the assertion and then rubber-stamp it.

What that signature is actually saying:

A documented framework exists covering all six elements from the Act

The framework fits how the company actually operates and where its risks sit

The controls run as designed, day to day, not just on paper

Significant control deficiencies are identified, evaluated and appropriately addressed.Listed companies get one more layer. Under SEBI’s LODR Regulations 2015, the CEO and CFO must certify to the board that any significant control deficiencies were disclosed to the auditor and audit committee. That certification is what the board’s statement rests on.

What does the statutory auditor check under IFC audits?

Under Section 143(3)(i), the auditor reports separately on whether internal financial controls over financial reporting were adequate and whether they operated effectively through the year, not just at closing.

This sits apart from the main audit opinion. It’s own paragraph, its own conclusion. The ICAI Guidance Note on Audit of Internal Financial Controls Over Financial Reporting (updated 2023) sets out how auditors get there, testing two things.

Design effectiveness: would this control, run correctly, actually catch a material error? A manual sign-off process built for paper invoices doesn’t transfer cleanly to an automated billing system just because someone copied the language across.

Operating effectiveness: does the control run as intended across the year, not just on the day the auditor shows up? That means sampling evidence from multiple points in the year, not a single snapshot.

Deficiencies auditors keep finding, year after year:

One person able to initiate, approve, and record the same transaction

Weak IT access controls, especially around who can change what

Missing review steps at period-end close

Revenue recognition controls that don’t match actual contract terms

Management overriding controls without documenting why

A material weakness pushes the audit report toward a qualified or adverse IFC conclusion. For listed companies, that carries regulatory weight beyond the report itself.

What framework should companies actually build on?

Most Indian companies build on COSO’s Internal Control Integrated Framework (2013), the same reference the ICAI Guidance Note points to. It’s not legally mandatory, but it’s what everyone expects to see.

COSO breaks controls into five pieces: control environment, risk assessment, control activities, information flow, and monitoring. The statute doesn’t require COSO by name. It requires the six elements under Section 134(5). COSO just happens to be the shared language auditors and audit committees use to talk about it.

Foreign-owned subsidiaries often start from the parent’s global framework, frequently SOX-based. That’s a reasonable starting point and a poor ending point. SOX was built for US GAAP and SEC reporting. Ind AS has its own logic. A framework lifted wholesale from the parent, without recalibrating for Indian accounting standards and the entity’s actual risk profile, tends to fail exactly where it matters.

What happens when internal financial controls in India requirements aren’t met?

Section 134(8) applies where there is a contravention of Section 134, such as:

  • failure to comply with Board’s Report requirements; 
  • omission of mandatory disclosures; 
  • non-compliance with the Directors’ Responsibility Statement requirements.
  • Penalty of Rs. 3 lakh for the company, Rs. 50,000 for each officer in default.
  • That’s the statutory floor. The real cost usually runs deeper:
  • Mandatory disclosure in the annual report
  • The audit committee has to produce and defend a remediation plan
  • Credit rating assessments can move
  • It shows up in investor and lender due diligence, often at the worst time
  • In case of Listed Company, SEBI can open an inquiry into whether it also breached LODR disclosure duties

Here’s the piece most foreign-owned subsidiaries miss entirely: a weakness found in the Indian entity can ripple back into the parent’s own consolidated controls reporting, if that parent is listed abroad and answers to its own internal controls regime.

Conclusion

Internal financial controls in India is a board obligation first, an audit deliverable second. The Directors’ Responsibility Statement carries directors’ names, not the CFO’s and not the internal audit head’s.The Board is responsible for establishing and maintaining internal financial controls, while the statutory auditor independently reports on them where required..

Most deficiencies trace back to the same root: a control framework built three years ago that never got updated as the business grew, systems changed, or new product lines came online. Controls that made sense then may not match the risk the company carries now.

Corporate Legit Consulting LLP works with Indian companies and foreign-owned subsidiaries on building internal financial controls in India frameworks, preparing for IFC audits, getting the Directors’ Responsibility Statement right, and remediating weaknesses auditors have already flagged. Talk to us before the audit cycle starts, not after the report lands.

Frequently Asked Questions

1. Which companies must comply with internal financial controls requirements in India?

Section 134(5)(e) expressly applies to listed companies. In addition, Rule 8(5)(viii) of the Companies (Accounts) Rules, 2014, requires unlisted public companies must comply with internal financial controls India requirements . Private Limited companies that are subsidiaries of listed entities or fall within the prescribed class are also required to comply. Small companies under Section 2(85) and One Person Companies are specifically exempted.

2. What must the board certify about internal financial controls in the Directors' Responsibility Statement?

The board must confirm that it has laid down internal financial controls, that such controls are adequate for the company’s operations and risk profile, and that they are operating effectively. This is a statutory confirmation made by the Board itself and is independent of the statutory auditor’s opinion..

3. What does the statutory auditor report on regarding internal financial controls India?

Under Section 143(3)(i) of the Companies Act 2013, the statutory auditor must report whether the company has adequate internal financial controls with reference to financial statements and whether those controls were operating effectively. This IFC audit India opinion appears as a separate paragraph in the statutory audit report and is independent of the main audit opinion on the financial statements.

4. What is a material weakness in internal financial controls and what happens when one is found?

A material weakness is a deficiency or combination of deficiencies in internal financial controls in India such that there is a reasonable possibility that a material misstatement in the financial statements would not be prevented or detected and corrected on a timely basis. When found, the auditor issues a qualified or adverse IFC opinion, the company must disclose it in the annual report, and the audit committee should evaluate and remediate the deficiency promptly.. For listed companies, SEBI may review the disclosure for LODR compliance.

5. What framework should companies use to build internal financial controls in India?

The ICAI ‘s Guidance Note on Audit of Internal Financial Controls over Financial Reporting specifically recognises the COSO Internal Control Integrated Framework (2013) as an internationally accepted framework. Most Indian companies use COSO as the design and documentation framework for internal financial controls India. It organises controls across five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. Using COSO provides the taxonomy that auditors and audit committees expect when reviewing IFC documentation.

  • Previous Business Valuation in India: What It Is, How It Works and Why Getting It Wrong Is Expensive
  • Next Warranty and Indemnity Insurance in Indian M&A Transactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Corporate Advisory Structuring in India: What It Covers and How Firms Like RSM Astute Approach It
  • FEMA Compounding: What It Is, When You Need It, and What Changed in 2024 and 2025
  • Virtual CFO for Startups: What It Is, What It Costs and When You Need One
  • BPO Company Setup in India: Compliance Guide
  • Business Valuation in India: What It Is, How It Works and Why Getting It Wrong Is Expensive

Recent Comments

No comments to show.

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • January 2021
  • November 2020
  • September 2019

Categories

  • Audit Services in India
  • Company Law Compliance India
  • Corporate Legal Services India
  • DTAA Compliance in India
  • FDI
  • Fema Compliance for Foreign Companies in India
  • Finance
  • Foreign Company Setup in India
  • GST Company Laws
  • GST Compliance
  • Income Tax
  • India Entry Services
  • International Financial Services
  • International taxation
  • IT Technology
  • Secretarial & Corporate Legal Compliance
  • Uncategorized
  • Wholly Owned Subsidiary in India
Corporate Legit Logo
We are a private consultancy firm. We only provide documentation & application support. We are NOT a government department or associated with any government authority.
Facebook Youtube Linkedin
Linkedin Youtube

CONTACT US

  • +91 9990607535
  • office@corporatelegit.in
  • A-77, Second Floor, Sector-4, Noida 201301, New Delhi NCR, India
  • ChatGPT Logo
  • Perplexity Logo
  • Claude Logo
  • X Grok Logo
  • Google Search Logo

OUR SERVICES

  • India Entry Services
  • Corporate Secretarial & FEMA
  • Corporate Legal
  • Direct & Indirect Taxation
  • Regulatory Compliances & Audits




    Whatsapp
    Copyright © 2026 Corporate Legit
    Phone-square
    Get in Touch



      Book a Consultation





            Talk to Our Expert

            Error: Contact form not found.

            Japan Market Entry Form

            Error: Contact form not found.